Casbaneiro, also known as Metamorfo, is a Windows banking Trojan targeting online-banking users in Latin America, including victims in Argentina, Peru, Colombia, and Mexico. It is distributed through phishing emails using invoice- and legal-notice-themed PDF lures. Recent delivery chains have used an HTA downloader and separately retrieved AutoIt components to unpack and launch the final payload.
Casbaneiro establishes persistence using a Windows Startup-folder shortcut and uses process injection to execute its payload within legitimate Windows processes. It employs anti-analysis measures including geographic filtering of delivery, language-based execution restrictions, runtime reconstruction and decryption of configuration strings, and communication workflows intended to complicate automated inspection and network analysis.
The malware collects victim and system information, including Microsoft Outlook address-book entries and email sender and recipient metadata, and exfiltrates collected data to attacker-controlled infrastructure. It delays primary command-and-control activity until the victim accesses a targeted banking website. During targeted online-banking sessions, it can support fraud through fake banking windows, clipboard manipulation, keyboard control, file execution, and command execution. No specific threat actor attribution is established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Several behaviors in this sample are similar to those observed in the Casbaneiro (Metamorfo) banking malware lineage.
The point of all this is to drop Casbaneiro, a classic banking Trojan that triggers when victims visit their cryptocurrency or financial service providers online.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
“Visitors outside the selected countries are redirected to legitimate sites such as Google or YouTube, while targets are served a page that silently downloads a Base64-encoded ZIP archive.”
The decryption key and encrypted strings are split into multiple fragments, which are concatenated at runtime whenever the malware needs to decrypt and use a specific string.
The malware injects the payload into mobsync.exe only if RegSvcs.exe does not exist.
Upon execution, Casbaneiro decrypts required strings, including cryptocurrency addresses, global ID, and a data exfiltration URL.
Inside the archive, an HTA file fetches further script content and checks the device for analysis environments and approved operating-system languages.
The Trojan does not immediately use its main command channel. It waits until the victim visits one of the targeted bank websites, then sends system information and accepts commands.
Only when the victim accesses websites related to targeted banks through a web browser does the malware send information about the infected computer to the server and initiate C2 communication.
During initialization, the malware creates a mutex named GlobolID-4465173{Username} to prevent concurrent execution.
Casbaneiro incorporates several techniques designed to hinder analysis, including an endpoint that deliberately returns HTTP 403 responses... These techniques can make the malware and its infrastructure appear inactive or inaccessible to automated analysis tools.
“It builds an identifier from the computer name, user name and executable name.”
It builds an identifier from the computer name, user name and executable name, then uses a hash of that value to track activity and avoid repeating some actions.
Casbaneiro incorporates several techniques designed to hinder analysis, including an endpoint that deliberately returns HTTP 403 responses... These techniques can make the malware and its infrastructure appear inactive or inaccessible to automated analysis tools.
“[Casbaneiro] collects address-book entries and Outlook sender and recipient details.”
A second server returns HTTP 403 when it receives Base64-encoded victim data. Rather than signalling failure, that response is part of the process; any other status makes the malware retry.
A second server returns HTTP 403 when it receives Base64-encoded victim data... The campaign also sends different information to different servers and uses malformed HTTP requests.
128 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
146 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Windows-focused banking Trojan delivered through personalized phishing PDFs, Base64-encoded ZIP archives, HTA downloaders, and AutoIt-based staged loaders. It performs anti-analysis and regional filtering, persists via a Startup shortcut, injects into RegSvcs.exe or mobsync.exe, collects address-book and Outlook email metadata, and waits for visits to targeted bank sites before contacting its command infrastructure. It supports keyboard control, clipboard pasting, file execution, command execution, and bank-targeted fake-window functions. Its communications include malformed HTTP requests and an expected HTTP 403 response used as part of its data-exfiltration workflow.
Windows-focused banking Trojan distributed through phishing PDF lures and staged HTA/AutoIt downloads. It uses regional filtering and anti-analysis checks, injects into RegSvcs.exe or mobsync.exe, establishes Startup-folder persistence, harvests address-book and Outlook email metadata, and activates its principal command channel when a victim visits a targeted banking website. It supports keyboard control, clipboard pasting, command/file execution, and fake banking windows to facilitate fraud.
A banking trojan delivered through phishing emails using a multi-stage HTA downloader and AutoIt loader. It injects its payload into a Windows process and supports financial fraud through clipboard injection and fake windows; it uses distributed data-receiving servers for network communications.
Windows-focused Latin American banking trojan delivered through phishing PDFs, an HTA downloader, and an AutoIt loader. It injects its payload into RegSvcs.exe or mobsync.exe, establishes Startup-folder persistence, targets bank-site activity before initiating C2, uses clipboard injection and fraudulent windows, and steals Outlook address-book and email sender/recipient data for unencrypted exfiltration.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.